"YOUR" Icon added to internet security settings

Discussion in 'Malware Help (A Specialist Will Reply)' started by candive, Jun 8, 2007.

  1. candive

    candive Corporal

    Hello all,

    I installed some new programs one was free ram xp by yourware?

    Now I have a security setting added to my internet settings "YOUR" that I cannot set or remove even after removing free ram from my HDD.

    I will try the Malware removal procedure by chaslang? I hope I spelled the name correctly.

    I was wondering if anyone has had this problem ("YOUR" added to internet security settings?)

    It also drops my security for Internet to the lowest setting.

    Thank you
     
    Last edited: Jun 8, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the 6 logs requested in the READ ME when you finish running the procedure. This program is not know to be malware as far as I know.

    What do you mean by internet security settings? Do you mean it has added itself to the Trusted Zone? If so, just remove it.
     
  3. candive

    candive Corporal

    Hi chaslang,

    I will post when finished.

    First, I have not been able to boot to SAFE mode yet it freezes during the loading description of drivers etc.

    Second, "YOUR" is now a "Zone"(red circle crossed out)to the right of "Restricted"

    This appears to be a very nasty.

    Leave it to me to find the bad ones !

    Back to post later, I hope.

    I have aquired a distaste for format and reload. (last resort)

    Thanks!

    p.s. I saw "Mavericks Matrix" in earlier scan.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you cannot run in safe mode, just run in normal boot mode as indicated in the READ ME.
     
  5. candive

    candive Corporal

    I have been up all night.
    In one of my scans "Show New" (or) "Get Run key" I found....
    "Mavericks Matrix"

    It is still there.

    I have regained control of my PC for now.
    It is changing things everywhere.

    We are not amused. well maybe a little.

    I will get some sleep and run the READ ME apps Properly.

    Will this garbage damage my PC??????

    Should I format or can I play with it awhile????

    Thanks

    Mr. C
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you attach the requested logs I have no idea what problems you really have so I cannot answer your question.

    That's up to you and also your abilities. There is more involved in a reinstall than most people think about. Especially to get back to a level of where you system is at. You have to consider all of the below:
    • you have to backup all you own data, settings, configurations etc and first you have to know what/where all of these are. And you have to have the medium (burnable media, second hard drive, tape drive [yuck] )
    • then you must make sure you have the necessary disks to reinstall not just your OS but all other software you use especially protection before going online
    • then fdisk, format, reinstall the OS
    • now reinstall all your software especially protection
    • get online (requires some setup and config that novices have problems with)
    • download updates for OS
    • download updates for protection software
    • download updates for all other software
    • tweak all software back the way you like it. Including Desktop settings, icons etc.
    • create all the folders that you use for everything in your normally routines
    • re-load from your backups to get data back, to get settings, Favorites,.....etc back
    • now over the next two weeks you will realize that you forgot to backup some stuff and also you will keep finding something else that you need to reinstall.
     
  7. candive

    candive Corporal

    The scans showed nothing, but I did notice the title "Maverick's Matrix" unfortunately I am unable to post as they are stuck on the laptop in question.

    It gets better my Multi DVD/CD Burner and USB's are now not being recognized.

    Checked BIOS.

    So I am not able to do a format.

    I am unable to save, Back ups do not work.

    Lucky for me I back up daily to separate media.

    I am unable to update drivers on web at all, I get blocked by Error messages I will note the error names for next post.

    But so far I am still amused.

    I will try to format by attaching a CD ROM to another port.

    If this is a program written by someone hire them quick, Luke use the Force!!

    Thank you

    Back later.
     
  8. candive

    candive Corporal

    I think I will try DOS.

    I have formatted more than a few times.

    Thank you chaslang.
     
  9. candive

    candive Corporal

    I was able to use System Back-up in safe mode.

    Laptop is back up, but I lost some logs.
    Should I post what I have or run the "READ ME" again?

    Mr. C
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are still having malware issues (and nothing your posted thus far really sounded like malware), you must run the READ ME and attach all 6 logs. Otherwise we are finished here.
     
  11. candive

    candive Corporal

  12. candive

    candive Corporal

    Title: Mavericks Matrix
    Severity: CRITICAL
    Description:
    A Trojan horse is a malicious program that is disguised as legitimate software. Trojan horse programs cannot replicate themselves, whereas viruses can do so. A backdoor is a method to gain unauthorized access to a system. It can be a separate program, or code embedded in another program.

    Mavericks Matrix is a backdoor Trojan affecting Microsoft Windows operating systems. It spreads by manual installation. When executed, Mavericks Matrix copies its backdoor server, matrix.exe, to the Windows System directory. It modifies the registry, or the system.ini and win.ini files, depending on the version of Windows running, so that the backdoor server runs whenever Windows starts up. The backdoor server default opens TCP port 1269 on the victim machine.

    A remote attacker can use the Mavericks Matrix client to gain unauthorized access to the victim system. The attacker can then perform such operations as: upload or download files, execute commands, restart Windows, control the mouse, send messages, get information about the infected system, and get passwords.

    Mavericks Matrix has many variants dated from May, 1999 to July, 2004.

    Affected Products:
    Microsoft Windows Undisclosed
    References:
    EID: 3294

    COPIED FROM THIS LINK www.juniper.net/security/auto/vulnerabilities/vuln1339.html - 11k
     
    Last edited: Jun 14, 2007
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing hides in RAM! As soon as your PC is shutdown, everything in RAM is gone. RAM is volitile memory.
     
  14. candive

    candive Corporal

    I was told the only way to be sure I got rid of Mavericks Matrix was to,

    Remove the partitions then remove the power source so it would not be able to hide in the partition or the RAM, nor would it be formatted to the floor.

    Then allow a complete format and partition in this way it could not be written to the floor (format)

    As you say Ram is Volitile it needs power to hold data.

    I am not talented enough to properly explain myself yet, in time.

    chaslang, Thank you for your help!
    I know it is appreceiated by all those that you help!!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes RAM requires power to maintain the data!

    I don't necessarily agree with the assessment on removing the malware however since you never attach any of the requested info from the READ ME, I cannot make any comments on what you may or may not have been infected with.

    In reality, the only 100% reliable way to remove any infection (not just what you mentioned) so you can be sure that it is totally gone is to do a total destructive reinstall (re-partition, format, re-install from guaranteed original media from Microsoft). You cannot even backup any data of files in any form since they could be infected. However, no one (or at least very very rarely does anyone) chose to take this course of action.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds